Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
To mitigate this issue, avoid processing untrusted XML catalog files with applications linked against libxml2. Users should exercise caution when opening or processing XML documents from untrusted sources, as a malicious catalog could lead to application crashes. Where possible, restrict the ability of applications to load external XML catalogs, or ensure that only trusted catalog files are used.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 17 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML catalog parsing. This occurs when a `nextCatalog` element lacks its mandatory `catalog` attribute, leading to the application crashing and causing a Denial of Service (DoS). | |
| Title | Libxml2: libxml2: null pointer dereference parsing nextcatalog without catalog attribute | |
| First Time appeared |
Redhat
Redhat enterprise Linux Redhat hummingbird Redhat openshift |
|
| Weaknesses | CWE-476 | |
| CPEs | cpe:/a:redhat:hummingbird:1 cpe:/a:redhat:openshift:4 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux Redhat hummingbird Redhat openshift |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-17T19:19:28.333Z
Reserved: 2026-08-19T17:15:10.735Z
Link: CVE-2026-76781
No data.
Status : Received
Published: 2026-09-17T16:17:42.070
Modified: 2026-09-17T20:18:15.480
Link: CVE-2026-76781
No data.
OpenCVE Enrichment
Updated: 2026-09-17T21:00:17Z